Senior Engineer - GISOCC IS Technology
Job Description
Responsibilities
As a Team Member, ensure that,
As a Team Member, ensure that,
- Guaranties confidentiality of information;
- Ability to work independently and in a team;
- Follow process and documentation;
- Good problem solving abilities and analytical skills;
- High inclination in reading and understanding technical documentation;
- Good Written and oral skills in English;
- High degree of commitment and diligence;
- Willingness to work 24x7 shifts.
- Strong expertise in Endpoint Security tools including monitoring, threat detection, and remediation.
- Developed and maintained security playbooks and automated workflows to improve incident response efficiency.
- Extensive experience in Incident Response (IR), including investigation, triage, containment, eradication, recovery, and post-incident analysis.
- Strong understanding of the MITRE ATT&CK framework, Cyber Kill Chain, IOC/IOA analysis, and threat detection methodologies.
- Investigate and triage DLP alerts to identify potential data exfiltration, policy violations, or insider threats.
- Good working knowledge of SIEM platforms for log collection, event correlation, alert triage, threat hunting, and security monitoring.
- Strong knowledge of log analysis, including Windows Security, System, and Application logs, authentication events, account lockouts, privilege escalation, and suspicious process execution.
- Proficient in Scripting and Automation using PowerShell, Python, and Bash to improve operational efficiency.
- Good knowledge of Vulnerability Management, including scanning, risk prioritization, and remediation tracking.
- Good understanding of Operating Systems: Windows Server, Windows 11, and Linux distributions.
- Hands-on experience working with Linux OS administration and security hardening.
- Experienced in validating and verifying system security requirements, performing security analysis, and designing secure system architectures.
- Conduct root cause analysis (RCA) for security incidents and provide remediation recommendations
- Work with IT, Cloud, Network, and Application teams during incident response.
- Skills
- Excellent communication skills are a must!
- Strong understanding of task, project and responsibilities ownership
- Ability to work independently and as part of a team
- Willing to work off-hours in an on-call schedule
- Creative and innovative thinking
- Good organization skills to balance and prioritise work
- Analytical and problem solving skills to troubleshoot issues
- Graduation (BSC/ BCA/ BE/B.Tech/MSC IT) with no history of arrears .
- 5-7 years of CyberSecurity Experience
- 5 to 7 years experience working within SOC Operations, Endpoint detection response & incident handling, threat hunting, vulnerability management
- Experience working in Ticketing tools like ServiceNow, JIRA etc.,
- Experience with OS like windows, linux for analysis
- Experience in SIEM tools for managing Playbooks
- Experience with DLP Incidence handling
- Experience with Log Source Monitoring
- Experience in Automation & AI (Optional)
More Info
Key Skills
SIEM platforms
Linux OS administration and security hardening
Endpoint Security tools
Cyber Kill Chain
